dggun

Password Strength Checker

Type a password to see how strong it is. The checker runs entirely in your browser — nothing is sent anywhere — and looks at length, character variety, common and leaked-style passwords, keyboard patterns, repeated characters, sequences and dates. It gives a rough estimate of how long guessing would take and explains exactly what would make it stronger. A generator creates strong random passwords and passphrases.

Password strength checker

Generate a strong password

Tip: rather than typing a password you actually use, test one with the same structure.

Password Security Kit

Printable password security checklist, a household account inventory workbook (no passwords stored), a 2FA setup tracker and a family online safety guide.

Formats: PDF, DOCX, XLSX. Instant download after payment (link valid 72 hours, up to 5 downloads). AI-assisted: the templates were drafted with AI help and reviewed and laid out by Kedop.

$3.00 USD, one-time

Secure card checkout by Stripe. Full refund within 7 days — see the refund policy and license.

What makes a password strong

A strong password is one an attacker cannot guess in any reasonable time. Two things matter most: length and unpredictability. Each extra character multiplies the number of possible passwords, so a long password is far harder to crack than a short complex one. But length only helps if the password is not predictable — “Password12345678” is long and still weak because it follows patterns attackers try first. The strongest passwords are long and random, or long passphrases made of several random words.

How the checker works

The checker first estimates entropy — the number of bits of randomness — from the length and the types of characters used: lowercase letters (26 options per character), uppercase (26), digits (10) and symbols (about 33). It then subtracts for patterns that make guessing easier: common passwords, dictionary words, keyboard walks such as “qwerty”, sequences like “abc” and “123”, repeated characters, years, and the very common “Capital-word-numbers-symbol” structure. The result is a rough strength rating and crack-time estimates for three attack scenarios.

Understanding crack-time estimates

ScenarioGuesses per second (illustrative)When it applies
Online, throttledAbout 100An attacker trying logins on a website that limits attempts
Offline, slow hashAbout 10,000Stolen password database protected with bcrypt, scrypt or Argon2
Offline, fast hashAbout 10 billionStolen database with unsalted fast hashes, cracked on GPUs

These are illustrative rates, not measurements of any particular system. Real attackers use huge lists of leaked passwords and rules that transform them, so predictable passwords fall much faster than the raw entropy suggests. That is why the checker penalises patterns heavily.

Examples

PasswordAssessment
123456Very weak — among the most common passwords in leaked lists
Summer2024!Weak — common word, a year and a trailing symbol
P@ssw0rdVery weak — substitutions like @ for a and 0 for o are well known
correct-horse-battery-stapleStrong length, but famous — never use published examples
tulip-orbit-kettle-walrus-quartz-58Very strong — random words from the generator
k7#Qm2!vR9xL@4pWVery strong — 16 random characters

Passphrases vs random passwords

Random character passwords pack the most strength into the fewest characters but are hard to remember and type. Passphrases — several randomly chosen words — are easier to remember and type on phones, and five or six random words give strong protection. The key word is random: words chosen by a person (a favourite song lyric or quote) are far more predictable than words picked by a computer. The generator uses your browser’s cryptographically secure random number generator for both types.

Best practices

What current guidance says

Modern guidance such as the US NIST digital identity guidelines favours longer passwords and passphrases, checking new passwords against lists of known compromised passwords, allowing all characters including spaces, and not forcing arbitrary composition rules or regular expiry. Many organisations now require a minimum of 12–15 characters for staff accounts and encourage password managers and multi-factor authentication.

Worked example

The default password “Summer2024!” is 11 characters with all four character types, which sounds good — about 72 bits by raw calculation. But it follows the most common structure (capitalised word, digits, symbol), contains a year and a season word that appears in many leaked lists. After those penalties the checker rates it weak, and a fast offline attack could guess it in seconds. A generated five-word passphrase such as “maple-radar-velvet-otter-cabin-41” rates very strong while still being easy to type.

Is it safe to test a password here?

The checker runs entirely in your browser with no network requests — you can disconnect from the internet and it still works. Nothing is logged, stored or sent. Even so, good practice is not to type real passwords into any website you do not need to; test a password with the same structure instead, then create your real one in a password manager.

Privacy

No data leaves your device. The page does not store what you type, and the generator uses the browser’s built-in secure random numbers.

Frequently asked questions

How long should a password be?

At least 12 characters, and 16 or more for important accounts; passphrases of 5–6 random words are also strong.

Are symbols required for a strong password?

They help a little, but length and randomness matter more.

Is it safe to type my password here?

The checker runs locally and sends nothing, but testing a similar password is best practice.

Why is P@ssw0rd weak?

Common letter-to-symbol substitutions are the first variations attackers try.

What is password entropy?

A measure in bits of how unpredictable a password is; each extra bit doubles the guesses needed.

Should I use a password manager?

Yes, it lets you use a unique random password for every account.